CVE-2020-12627: Janeczku Calibre-Web

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.

Affected products

  • Janeczku Calibre-Web: version 0.6.6 only

Published 2020-05-04. Last modified 2026-06-17.